A publicly accessible database linked to reverse image search service ClarityCheck exposed more than nine million images, including photographs of adults, teenagers, and children.
Cybersecurity researcher Jeremiah Fowler discovered the database, which was neither password-protected nor encrypted. It contained approximately 9,042,977 image files, amounting to 450.2GB of data. Most were stored in folders labeled “faces” and “profiles.”
Fowler said the images he reviewed included profile pictures, screenshots, and physical photographs that appeared to have been uploaded for reverse image searches or identity verification.
“I recently discovered a publicly exposed database that was neither password-protected nor encrypted,” Fowler said. “The database contained approximately 9,042,977 image files totaling 450.2GB of data.”
His investigation linked the files to ClarityCheck, a US-registered company that offers an online investigation service using reverse image search. Fowler found the cloud storage database URL in the source code of a public page. He could not determine whether ClarityCheck managed the database directly or whether a third-party contractor was responsible for it.
Fowler sent a responsible disclosure notice to ClarityCheck, and the database was subsequently restricted from public access. The company replied to thank him for reporting the issue and said it had acted to protect users’ data and privacy.
It is not known how long the database was publicly accessible or whether anyone accessed the records before Fowler found them. He said an internal forensic investigation would be needed to determine whether the data had been downloaded by third parties.
Why facial images pose a particular privacy risk
A facial image does not need to have a name or email address attached to raise privacy concerns. In a reverse image search, the photograph itself can be used to find other information about the person pictured.
“Facial images are fundamentally different from many other types of personal data because the face itself is the identifying characteristic and is used as a search key,” Fowler said.
ClarityCheck says its service can help users identify people, detect catfishing, investigate suspicious online profiles, and carry out OSINT-based searches. Its website also states that its reverse image search can be used to find names, social profiles, and a person’s online presence.
At the same time, the company’s disclaimer says it does not provide facial recognition or identity verification and instructs users to upload only images they have the right to share.
Fowler said some of the images he saw may have come from social media and dating accounts, private profiles, screenshots, or physical photographs. In some cases, the people pictured may not have known that someone else had uploaded their image to the service.
The exposed database also contained images of children. Fowler said he reviewed only the records necessary to verify and document the exposure and did not download the data.
Images appeared to remain beyond the stated 14-day limit
ClarityCheck’s terms say images submitted for reverse image lookup are stored for 14 days before being automatically deleted.
Fowler found images in the exposed database with timestamps that exceeded that period. He said this raised questions about how the company’s retention policy was being applied and how uploaded images and consent were being managed.
The timestamps alone do not establish why those images remained in the database. But the finding puts the amount of biometric data being retained, and the length of time it was being kept, under scrutiny.
Exposed images could support impersonation and scams
A facial image on its own is generally not enough to steal someone’s identity. Fowler warned that it could become more useful to criminals when combined with information available elsewhere.
Someone could potentially identify the person in a photograph and use the image to create a fake social media profile. It could also be used in phishing messages or impersonation scams targeting the person’s friends, family members, or colleagues. An attacker would not necessarily need to identify the person at all and could instead use the photograph as a generic fake persona.
AI tools also make photographs easier to manipulate and analyse. Fowler pointed to the potential for large image collections to become useful for facial recognition, tracking, or surveillance as the technology develops.
He did not find evidence that this happened to the ClarityCheck images. Nor did he claim that criminals, data brokers, nation-states, or other third parties accessed the database. The concern is based on what could be done with an exposed collection of facial images, not evidence that the images were misused.
Facial data remains useful long after an exposure
Facial data presents a problem that passwords and payment card details do not: people cannot replace it after an incident.
“Once biometric facial data is exposed, individuals cannot simply reset or replace their faces in the same way they would change a password or credit card number,” Fowler said.
Advances in AI could also make old image collections more useful. Fowler noted that AI models can already match unlabeled facial images at scale without names or profile information attached to them. He warned that large image datasets could potentially be used to develop or improve facial recognition, tracking, and surveillance technologies.
Companies need to limit how much facial data they keep
Fowler advised organisations collecting facial images to treat them as sensitive information and protect them to the same standard as other forms of personally identifiable information.
Encryption, restriction of access via role-based restrictions, multi-factor authentication, and ensuring that image stores are not accessible from the Internet are some of his recommendations. Other methods include performing security evaluations and penetration testing to find vulnerabilities before the data is compromised.
He also urged companies to keep as little biometric data as possible and securely delete records when they are no longer needed. Where possible, organisations should avoid retaining raw facial images.
Those who suspect that their facial images have been stored or used without their consent must inform the organisation that holds such images and the respective social networking site. According to Fowler, those people must notify the relevant privacy or data protection agency when necessary and inform their friends and relatives of any unusual messages or attempts at impersonation.
ClarityCheck had restricted access to the database by the time Fowler’s findings were published. It remains unknown how long the images were exposed or whether anyone else found them during that period.
Fowler stressed that he is not alleging wrongdoing by ClarityCheck or related entities. His investigation did not establish that the data was exploited or that any internal systems were compromised.
Information Security Buzz News Editor
Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.
The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.


